Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber brief: VPN edge-device risk + “ClickFix CAPTCHA” traps

What small and medium-sized businesses should look out for today.

High Sunday 19 July 2026, 18:15 UK time
Today’s look-out: Remote access/VPN compromise and staff tricked into running “verification” steps

What to look out for today

1) VPN / remote access gateways under pressure: Reports of SonicWall SMA appliances being exploited as zero-days before public disclosure highlights ongoing risk to internet-facing remote access devices.

2) “ClickFix” / fake CAPTCHA verification: A campaign used CAPTCHA-style prompts to trick people into infecting their own machines with malware. The technique is simple and can be repurposed beyond the original targets.

3) Supplier/update-channel abuse: A separate report describes attackers abusing a product update mechanism to reach victims. This is a reminder to treat software updates and management tools as high-trust pathways.

Why this matters to smaller businesses

  • Business disruption: If a VPN/remote access box is compromised, attackers may gain a foothold that leads to account takeover, data access, ransomware, or prolonged IT downtime.
  • SMEs are exposed by default: Many smaller organisations rely on a single edge device (VPN) and outsourced IT. If that device is reachable from the internet, it’s a high-value target.
  • Staff are the delivery route: Fake “verification” or CAPTCHA steps can bypass technical controls by persuading users to do the risky action themselves.
  • Supply chain risk is real: If an update channel or management tool is abused, even well-run organisations can be impacted quickly.

Warning signs

  • Staff report being asked to complete a “CAPTCHA” that involves extra steps beyond ticking a box (e.g., instructions to copy/paste something, run a command, install a plugin, or “verify you’re human” by enabling settings).
  • Unexpected remote access behaviour: new VPN user accounts, logins at odd hours, or login attempts from unusual locations.
  • Unplanned VPN outages, slowdowns, or repeated reboots of remote access devices.
  • Unexpected prompts to approve sign-ins, MFA fatigue requests, or “security verification” emails/messages related to remote access.
  • Unusual update prompts for networking/security tools or requests to “manually apply” an update from an emailed link.

How attackers may exploit the situation

  • Edge-device compromise: Attackers target internet-facing VPN/remote access appliances to gain deep access without needing a phish first.
  • Social engineering with “ClickFix”: Victims are tricked into running steps that install malware, often framed as fixing an error or completing verification.
  • Abusing trusted tooling: Where update mechanisms or management pathways are misused, attackers can distribute malicious changes while appearing legitimate.

What to do today

  • Send a 2-minute staff note: “CAPTCHAs never require you to run commands, install software, or paste text. If a verification prompt asks for anything beyond a checkbox/image selection, stop and report it.”
  • Confirm remote access ownership: Identify who manages your VPN/remote access device(s) and ensure you can reach them quickly (including out-of-hours contact if you rely on remote work).
  • Review access basics: Ensure MFA is enforced for remote access and admin portals, and remove old accounts that no longer need VPN access.
  • Log and alert: Make sure VPN login events are being monitored (even if it’s just daily review) and that you’ll know quickly if configuration changes occur.
  • Prepare for disruption: Check you have an offline way to reach staff/customers if email or VPN is down (phone list, alternate comms channel).

Ask your IT provider

  • Do we have any SonicWall SMA devices (or other internet-facing VPN gateways)? Who is responsible for monitoring and emergency response?
  • How quickly do you assess and act on reports of in-the-wild exploitation against remote access appliances?
  • What logs do we retain for VPN access and admin changes, and for how long?
  • Do we have a tested plan to revoke VPN sessions, rotate credentials, and confirm no persistence if we suspect compromise?
  • How do you validate software/firmware updates for networking and security tools (and prevent “manual update from an email link” scenarios)?

Patch watch - only one short paragraph, and only if relevant

If you use SonicWall SMA or similar remote access appliances, treat vendor security updates and provider guidance as time-sensitive. The key SME action is not researching technical details, but confirming ownership, monitoring, and a rapid “is this exposed and are we protected?” check with your IT provider.

One action today

Send a short staff alert: CAPTCHAs/“verification” pages should never ask you to run commands, paste text, or install anything—stop and report immediately.

Related Actions On Cyber resource

CTA: Use the Actions On Cyber “Suspicious email & fake verification (CAPTCHA/2FA) triage checklist” for staff and front-desk teams.

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.